This project demonstrates the investigation and validation of Suricata Intrusion Detection System (IDS) alerts using packet-level analysis in Wireshark. A network traffic capture (PCAP) was analyzed to determine whether the generated alerts represented legitimate security events or false positives.
The investigation focused on two high-priority Suricata alerts associated with the LandUpdate808 exploit kit. By correlating IDS alerts with DNS queries, DNS responses, and TLS handshake data, the investigation confirmed the alerts as True Positives.
- Configure and use Suricata to analyze a PCAP file.
- Investigate IDS alerts generated during traffic analysis.
- Validate Suricata detections using Wireshark.
- Identify Indicators of Compromise (IOCs).
- Produce a professional incident report documenting the investigation.
- Suricata
- Wireshark
- Kali Linux
- macOS
- Git & GitHub
- Intrusion Detection System (IDS) Analysis
- Network Traffic Analysis
- DNS Investigation
- TLS Handshake Analysis
- Packet Capture (PCAP) Analysis
- Alert Validation
- Indicator of Compromise (IOC) Identification
- Incident Documentation
The investigation identified suspicious communication between an internal host and the domain hillcoweb.com. Analysis confirmed the following sequence of events:
- Suricata detected a suspicious DNS lookup.
- Wireshark confirmed the DNS query from the internal host.
- The DNS server resolved the domain to an external IP address.
- The endpoint initiated an HTTPS connection.
- TLS analysis confirmed the Server Name Indication (SNI) contained hillcoweb.com.
- Both Suricata alerts were validated as True Positives.
| Finding | Result |
|---|---|
| Internal Host | 10.6.13.133 |
| Suspicious Domain | hillcoweb.com |
| External IP | 67.217.228.199 |
| Classification | True Positive |
| Confidence | High |
Suricata-Alert-Analysis/
│
├── README.md
├── Incident-Report.md
├── IOC-List.md
├── Screenshots/
│ ├── 01-fast-log.png
│ ├── 02-dns-query.png
│ ├── 03-dns-response.png
│ ├── 04-tls-sni.png
│ └── 05-alert-summary.png
└── LICENSE
- Incident Report: Incident-Report.md
- Indicators of Compromise: IOC-List.md
This project reinforced the importance of validating automated IDS detections with packet-level evidence. By correlating Suricata alerts with Wireshark analysis, I developed practical experience in alert triage, network traffic analysis, IOC identification, and professional incident documentation.
This project was completed in a controlled lab environment using publicly available traffic captures for educational purposes.



